Password generator

Secure password generator

Generate cryptographically random passwords with custom length and character types. Nothing leaves your browser.

What makes a password secure?

Password security is measured by entropy, the number of possible combinations an attacker must try to guess your password by brute force. Entropy is calculated as log2(charset_size ^ password_length). A 20-character password using all four character types (uppercase, lowercase, numbers, symbols) from a charset of ~90 characters has approximately 131 bits of entropy, effectively unguessable with current computing hardware.

Length is the single most important factor in password strength. A 16-character all-lowercase password has more entropy than an 8-character password using all character types. This is why modern security guidance (NIST SP 800-63B) recommends prioritising length (minimum 16 characters for sensitive accounts) over complexity requirements that lead users to predictable patterns like "Password1!".

This tool uses crypto.getRandomValues(), the browser's cryptographically secure pseudo-random number generator (CSPRNG). Unlike Math.random(), which is deterministic and predictable, CSPRNG output is genuinely random and suitable for security-sensitive use. The password is generated entirely in your browser's memory and is never transmitted anywhere. Close the tab after copying to remove it from memory.

Password management best practices

  • Use a different password for every account, a password manager makes this practical.
  • Enable two-factor authentication (2FA) wherever available.
  • Never reuse passwords across sites, a breach on one site exposes all reused passwords.
  • Passphrases (4+ random words) are both strong and memorable for master passwords.

Frequently asked questions

Is this password generator truly random?

Yes, it uses the browser's built-in crypto.getRandomValues() API, which is a CSPRNG seeded by OS-level entropy. It is appropriate for security-sensitive use.

Does my password get sent to your server?

No. The entire generation happens inside your browser. No network request is made. You can verify this in your browser's developer tools Network tab.

What does "entropy" mean?

Entropy (in bits) measures unpredictability. 80+ bits is strong for most use; 128+ bits is considered very strong. Doubling password length adds roughly 6 bits per character.